Role Snapshot
Role Title
Audit Manager - Systems Audit & Access Governance
Department
System and Process Audit
Location
Tirupur, Tamil Nadu (on-site;
travel within group companies as required)
Team
Build and lead a team of 2–4 audit analysts
Experience
8–14 years in IT / Systems Audit or ERP Access Governance
Qualifications
CA Intermediate / MBA (Finance or IT) / CPA / ACCA
Certifications
CISA preferred — CISSP / CIA / CRISC advantageous
Industry
Manufacturing / Textiles / Retail — Multi-ERP, multi-application environment
Role Purpose
Single owner of user access governance, controls assurance, process audit, and continuous systems improvement across the entire application landscape. Hands-on and board-facing — equally comfortable extracting raw ERP data and presenting risk findings. We want someone dynamic and raring to make a measurable difference, not a passive reviewer.
Key Responsibilities
01 User Access Review
Reconcile all ERP/app accounts against live HR records;
disable leavers and dormant users;
establish JML process;
maintain User Access Register with quarterly owner-certification cycles.
02 Segregation of Duties
Build role-to-function matrices;
apply SoD rule library to identify conflicts (e.G. create-vendor/approve-payment);
prioritise by risk;
track remediation in a living Risk Register.
03 Least Privilege
Compare assigned permissions vs actual usage;
produce Entitlement Heat Map;
drive rationalisation programmes;
establish bi-annual re-certification for all privileged accounts.
04 Access Control Vulnerabilities
Assess authentication, MFA coverage, PAM controls,
API/middleware gaps, and logging adequacy;
produce prioritised Vulnerability Register with risk ratings and mitigations.
05 Management Reporting & Follow-Up
Prepare risk-rated audit reports;
maintain CAP tracker;
conduct monthly follow-up reviews;
escalate overdue critical actions;
produce Quarterly Governance Dashboard for the board.
06 Process Controls Review
Walkthrough P2P, O2C, R2R, H2R and Inventory cycles;
identify control gaps and single points of failure;
recommend preventive/detective controls;
re-audit remediated areas.
07 Redundancy & Productivity
Identify duplicate functions, unused modules, and manual re-keying steps;
quantify effort cost;
prepare rationalisation business cases with productivity impact projections.
08 AI & Advanced Analytics
Deploy AI anomaly detection;
run SQL/Python/ACL population-level tests;
automate reconciliations via RPA;
design Continuous Monitoring Framework with real-time risk dashboards.
09 Analytical Reporting & Abnormality Detection
Prepare data-driven reports with Benford's Law, duplicate-payment, and three-way match tests;
profile user behaviour anomalies;
produce consolidated Master Exception Reports.
10 Master Data Governance
Review Vendor, Customer,
Item, CoA and Employee masters for duplicates and orphaned records;
detect unauthorised changes;
implement governance framework with data stewards and cleanse cycles.
Education & Certifications
- CA Intermediate / MBA (Finance or IT) / CPA / ACCA
- CISA strongly preferred
- CIA / CISSP / CRISC / SAP GRC advantageous
- A Degree/Diploma in CS or any IT field is a plus
Experience
- 8–14 years in IT/Systems Audit or ERP Access Governance
- Hands-on with ≥ 2 years of: SAP, Oracle, MS Dynamics or equivalent
- SoD analysis, access reviews, and least privilege in multi-system environments
- Board-level audit reporting and CAP closure track record
- Manufacturing / Textiles / FMCG background preferred
Technical Skills
- ERP user admin, role config, authorisation, and log extraction
- SQL / Python / ACL / IDEA for population-level data testing
- Power BI / Tableau for management dashboards
- AI anomaly detection and LLM-assisted audit tools
- RPA / scripting for audit automation
- ISO 27001, COBIT, ITIL, SOX awareness
Behavioural
- Dynamic, action-oriented — finds problems and drives resolution
- Translates technical findings into plain board-level language
- Owns findings through to closure, not just the report
- Resilient — comfortable raising uncomfortable truths
- Hunger to learn and adopt current tools and techniques
Work Schedule: 6 Days Working (Monday – Saturday)
Timings: 9:00 AM to 6:00 PM
Mode: Work From Office (WFO)
Interested candidates kindly share your updated resume to
[email protected]
📌 Audit Manager - Systems Audit & Access Governance (Tiruppur)
🏢 Ramraj Cotton
📍 Tiruppur